The release is well documented and has a clear license, tests in the repository, and regular recent publishing. Its only notable weakness is limited workflow hardening, with one unpinned action and no repository security-scanning tool.
86%
Total Score
100
100
88
100
Composer build tooling is present, but no repository security-scanning tool was detected. This is a modest transparency and maintenance gap, not evidence of unsafe code.
Version 0.13.0 is not a stable-major release, so its API may still evolve, but it is not marked as a prerelease and recent releases have been consistently published.
The single workflow was fully analyzed with no untrusted checkout, script injection, or audit findings. However, its one action reference is unpinned, leaving a modest reproducibility and workflow supply-chain weakness; the pull_request_target trigger has no dangerous sink here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/ai-platform Version ^0.13 | — | — |
symfony/http-client Version ^7.3|^8.0 | — | — |
symfony/ai-generic-platform Version ^0.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.